CVE-2024-45261

HIGHCVSS 8/10EPSS 0.48%

Last modified

CVE-2024-45261 is a high-severity vulnerability rated 8/10 on the CVSS scale. An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The SID generated for a specific user is not tied to that user itself, which allows other users to potentially use it for authentication. EPSS estimates a 0.48% chance of exploitation in the next 30 days.

Description

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The SID generated for a specific user is not tied to that user itself, which allows other users to potentially use it for authentication. Once an attacker bypasses the application's authentication procedures, they can generate a valid SID, escalate privileges, and gain full control.

Metrics

CVSS 3.1
8/10

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.48%

37.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Gl-InetMt2500 Firmware>= 4.6.2, < 4.6.4
Gl-InetAxt1800 Firmware>= 4.6.2, < 4.6.4
Gl-InetAx1800 Firmware>= 4.6.2, < 4.6.4
Gl-InetB3000 Firmware4.5.18
Gl-InetA1300 Firmware4.5.17
Gl-InetX300b Firmware4.5.17
Gl-InetX3000 Firmware4.4.9
Gl-InetXe3000 Firmware4.4.9
Gl-InetX750 Firmware4.3.18
Gl-InetSft1200 Firmware4.3.18
Gl-InetMt1300 Firmware4.3.18
Gl-InetE750 Firmware4.3.17
Gl-InetXe300 Firmware4.3.17
Gl-InetAr750 Firmware4.3.17
Gl-InetAr750s Firmware4.3.17
Gl-InetAr300m Firmware4.3.17
Gl-InetMt300n-V2 Firmware4.3.17
Gl-InetMt3000 Firmware4.6.2
Gl-InetAr300m16 Firmware4.3.17
Gl-InetMt6000 Firmware4.6.2
Gl-InetB1300 Firmware4.3.17

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2024-45261?
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The SID generated for a specific user is not tied to that user itself, which allows other users to potentially use it for authentication. Once an attacker bypasses the application's authentication procedures, they can generate a valid SID, escalate privileges, and gain full control.
How severe is CVE-2024-45261?
CVE-2024-45261 has a CVSS score of 8/10 (HIGH severity). The EPSS model estimates a 0.48% probability of exploitation in the next 30 days.
How do I fix CVE-2024-45261?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2024-45261?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST